If I have two servers (say web servers) located behind a layer4 switch, that act as a load balancer. server1 and server2 have the IPs (say) 1.2.3.4 & 1.2.3.5 and the load balancer is 1.2.3.6 Of course the DNS of the sites will point to 1.2.3.6 and clients from outside will see this. Now, will conntrack understand that the replies from 1.2.3.4 are really established connections that were destined for 1.2.3.6 ?? If not, any tips ? -- Mohamed Eldesoky www.eldesoky.net RHCE